Junglewise Threat Intelligence

CVE-2026-54157: LobeHub SSRF and cookie injection in webapi proxy

CVE-2026-54157 · Severity: critical · CVSS 9 · Published 2026-06-23

Technologies: LobeHub Lobe Chat, @lobehub/lobehub (npm), Lobehub. Vendors: LobeHub, npm.

Executive brief

LobeHub, an AI agent collaboration platform, contained a security flaw in its web proxy component. An attacker could use this flaw to make the LobeHub servers send unauthorized requests to other websites or internal systems. This could lead to the exposure of internal infrastructure details or the injection of malicious cookies into a user's browser, potentially allowing an attacker to hijack user sessions.

Technical details

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in LobeHub's `/webapi/proxy` endpoint. The root cause is a missing `checkAuth()` wrapper in the route handler located at `src/app/(backend)/webapi/proxy/route.ts`, which allows the endpoint to accept and fetch any URL provided in a POST body without authentication. Beyond standard SSRF, the proxy reflects upstream `Set-Cookie` headers, enabling attackers to perform cookie injection on the `lobehub.com` domain. This can be leveraged for session fixation attacks against Clerk-managed sessions or to leak Vercel deployment metadata (e.g., `X-Vercel-Id` headers). The vulnerability is resolved in version 2.1.57 by implementing proper authentication checks.

Affected products

  • LobeHub LobeHub < 2.1.57

Timeline

  • 2026-06-03: advisory: Initial GitHub security advisory published
  • 2026-06-23: disclosed: CVE-2026-54157 published to NVD
  • 2026-06-23: patched: Fix released in version 2.1.57

References

Related threats